Missing Authentication for Critical Function in Umbraco CMS - #VU153367

 

Missing Authentication for Critical Function in Umbraco CMS - #VU153367

Published: October 6, 2026


Vulnerability identifier: #VU153367
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain content identifiers and editorial activity information.

The vulnerability exists due to missing authentication in back-office SignalR hubs when accepting client connections. A remote attacker can connect to the exposed endpoints and receive real-time notifications to obtain content identifiers and editorial activity information.

The activity information includes when content is created or edited, including unpublished content. Content itself, credentials and management capabilities are not exposed, and the issue does not allow content to be changed.


Affected software

Umbraco CMS

Remediation

Install security update from vendor's website.

Umbraco CMS - addressed in versions 17.7.1, 18.2.1

External References

Related Security Bulletins